# IP Intelligence Briefing: 142.44.233.202/32
Classification: Cloud Hosting Infrastructure
Analysis Date: Current
Risk Assessment: Low Individual Risk / High Contextual Risk
## Executive Summary
IP 142.44.233.202 resolves to a cloud compute infrastructure asset operated by Ahrefs Pte Ltd on OVH hosting. While the individual IP carries a low risk score (35), the /24 subnet demonstrates high abuse density (0.7148) with 183 of 256 active siblings flagged as threats. The asset is currently firewalled with no open services exposed.
## Ownership and Infrastructure
- ASN: 16276 (OVH)
- Organization: Dmytro, Ahrefs Pte Ltd
- CIDR Block: 142.44.233.0/24
- Infrastructure Type: CloudCompute, Hosting-enabled
- Network Classification: Firewalled / No Services
## DNS and Service Profile
- PTR Hostname: proxy-ca003-san202.ahrefs.net
- Forward Resolution: proxy-ca003-san202.ahrefs.net (ahrefs.net)
- Open Ports: None detected
- TLS/HTTP Services: None active
- Email Authentication: SPF and DMARC records absent
## Threat Indicators and Reputation
- Risk Score: 35 (Low Risk)
- Abuse Confidence Score: Not scored
- Blacklist Status: Listed on 1 of 8 DNSBLs
- Tor Exit Node: No
- Known Campaign: None identified
- Threat Feeds: Empty
## Historical Observation Trends
Analysis of 30 observations indicates:
- Recent blacklist listings observed on 2026-06-20 with maximum severity: high
- Subnet classification consistently marked as "high_abuse"
- No persistent malicious activity detected
- Single threat observation recorded
- Ownership remains stable with no changes observed
## Neighborhood Risk Assessment
The /24 subnet (142.44.233.0/24) presents elevated contextual risk:
- Abuse Density: 0.7148 (high)
- Total Siblings: 256
- Active Siblings: 198
- Threat Siblings: 183
- Inherited Risk: 28
- Risk Distribution: 0 high, 94 medium, 6 low
## Recommended Security Actions
Given the subnet's high abuse density, the following defensive measures are recommended:
1. Monitor: Implement monitoring for traffic patterns to/from the subnet
2. Block List: Consider blacklisting the /24 range if threat correlation exists
3. Whitelist: The specific IP may be whitelisted if legitimate Ahrefs traffic is expected
4. Firewall Rule: Block inbound connections unless explicitly required
## Intelligence Context
This IP belongs to Ahrefs, a legitimate SEO analytics and data infrastructure provider. However, the hosting environment shows significant abuse activity within the same subnet. The IP itself is properly configured with firewalled services, suggesting either legitimate use or dormant infrastructure. The high abuse density of the /24 indicates either poor tenant isolation or targeted abuse campaigns affecting multiple addresses.
Bottom Line: Treat with caution. While the IP lacks direct threat indicators, its network context suggests elevated risk. Evaluate against known Ahrefs traffic patterns before allowing access.
This summary was generated by AI and may contain inaccuracies. Verify critical details independently.
๐ข Ownership & Registration
| Organization | Dmytro, Ahrefs Pte Ltd |
| ASN | AS16276 |
| Network Name | OVH-CUST-281059682 |
| CIDR Block | 142.44.233.0/24 |
| RIR | ARIN |
| Country | Singapore |
| Abuse Contact | โ |
๐ DNS Intelligence
| PTR | proxy-ca003-san202.ahrefs.net |
| Forward Confirmed | No โ PTR hostname does not resolve back to this IP (weak signal) |
| Forward Hostnames | proxy-ca003-san202.ahrefs.net |
๐ DNS Hygiene
| Hygiene Score | 40% (Fair) |
| SPF | Not configured |
| DMARC | Not configured |
| FCrDNS | Not verified |
| DNSSEC | Valid |
| CAA | Present |
โ๏ธ Network Classification
| Infrastructure | Infrastructure / Datacenter |
| Service Purpose | Firewalled / No Services |
| Network Tier | Tier 3 โ Basic operator with some routing infrastructure |
๐ Services & Open Ports
| Port | Service | Protocol | Banner |
|---|---|---|---|
| No open ports detected | |||
| Closed Ports | 22, 25, 80, 443, 3389, 8080, 8443 (0 open / 7 scanned) | ||
| Server | โ |
| HTTP Title | โ |
๐ TLS Certificate
| SANs | None |
| Valid From | โ |
| Valid Until | โ |
๐ฏ Confidence Breakdown
Per-dimension confidence scores based on source diversity and data freshness
| Dimension | Score | Sources | Observations |
|---|---|---|---|
| threat | 30% | 2 | 4 |
| routing | 30% | 3 | 4 |
| services | 12% | 2 | 2 |
| ownership | 30% | 3 | 3 |
| reputation | 32% | 1 | 3 |
| geolocation | 34% | 2 | 3 |
| Overall | 28% | 13 | 19 |
| Data Coherence | Mostly Consistent (80%) โ 1 contradiction(s) |
| Attribution | Moderate (50%) |
| OwnershipFCrDNSGeo ConsensusGeo PlausibleIRR MatchRPKI Valid |
๐ Observation Timeline ๐ Live
| First Seen | 2026-05-24 00:31:10 UTC |
| Last Seen | 2026-06-28 23:11:01 UTC |
| Profile Built | 2026-06-29 05:13:12 UTC |
| Data Freshness | Live |
| Signal Types | 28 |
| Total Observations | 31 |
Full dossier details are available via our API.